MonsterCloud owner charged over alleged secret ransom payments
Prosecutors say customers were billed as if MonsterCloud used its own recovery tools, while it allegedly paid attackers for decryptors instead.
Federal prosecutors say MonsterCloud’s owner, Zohar Pinhasi, ran a years-long ransomware recovery scheme that secretly paid attackers for decryptors while marketing his company as using proprietary recovery tools. He was indicted on September 23, arraigned in Brooklyn, and now faces one count of conspiracy to commit wire fraud plus two wire fraud charges tied to conduct alleged to have run from June 2018 through June 2023. The indictment says MonsterCloud paid ransomware crews much less than it billed customers, including one case where it allegedly paid about $8,200 and charged about $150,000, and another where it paid about $236,000 and billed roughly $380,000. Prosecutors also say the business used decrypted sample files as proof it could recover data, while in reality those samples came from the ransomware operators. If convicted, Pinhasi could receive up to 20 years in prison.
Why it matters
The case puts a recovery vendor’s billing and claims under criminal scrutiny, not just its technical methods. For companies hit by ransomware, it shows that the gap between what a provider says it does and what it actually pays for can now become a fraud case, with charges tied to a scheme prosecutors say generated more than $8 million in ransom payments and more than $19 million in recovery and remediation charges.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer